SQL Injection Vulnerabilities in Mantis from MantisBT
CVE-2005-4519

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
28 December 2005

What is CVE-2005-4519?

The Mantis Bug Tracker versions prior to 1.0.0rc4 are susceptible to multiple SQL injection vulnerabilities. Attackers can exploit these flaws through the manage user page (manage_user_page.php) by manipulating the 'prefix' and 'sort' parameters. Additionally, vulnerabilities are present in the 'sort' parameter in the view_all_set.php file, enabling remote attackers to execute arbitrary SQL commands, which can lead to unauthorized data access or manipulation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.